E-Business
Security: How Your Fingerprints Are Used
Your fingers have never been more important – they can unlock doors, open phones and even secure your savings, explains Greg Sarrail, Vice President, Solutions Business Development, Biometrics, HID Global in this article exclusive to Nigeria CommunicationsWeek.
Fingerprint scanners are considered the second most popular biometric devices by consumers around the world according to research undertaken by the 2016 Future Password Index. This research was defined by how interested people were in using fingerprints to verify their identity when handling their devices, banking and other forms of security.
Fingerprint biometrics saw a steady rise in popularity from 2014 to 2016 and remains one of the most trusted on the market today.
It is a trend that isn’t going to change anytime soon and this is further underscored by the rise in fingerprint scanners, ATMs, devices and solutions. Your fingerprint has become a coded key that only you can wield.
People are being asked for their fingerprints on a daily basis. When you go to work, transact at your bank, and when you apply for certain government documents.
Biometrics even play a fundamental role in the criminal justice system. However, not all biometric systems are created equal. There are important differences between specific systems, their capabilities, the data they access and the data they share.
Some biometric solutions are not linked to a shared network, so you could transact at your bank or enter your office park with your unique identity, but this information will not be shared anywhere else. The data is captured and secured by each individual system to ensure absolute security and controlled access.
In addition, it is important to know the difference between biometric verification and biometric identification as their applications vary, as do their relevance to your security. When undertaking biometric identification, you are asking – ‘Who am I?’
Whereas with biometric verification you are asking – ‘Am I who I claim to be?’ For example, once your fingerprint has been submitted to a specific database, an identification application would compare it against a larger database of fingerprints that are associated with identities. If your fingerprint is found within that database, then the question of ‘Who am I?’ has been answered. This is biometric identification in a very simple nutshell.
When it comes to biometric verification and proving an identity, there is a need to add in some extra factors that can support the process and make it more secure. These can be account numbers, credit cards, or even smart devices.
The system then pulls up the biometric data associated with your fingerprint and attempts to make a match. It’s important to note that the verification process doesn’t examine all fingerprint data for all users to find a match. Instead it checks to see if the fingerprint template that’s presented to the system is the same one that was originally enrolled, and it provides a quick answer.
Biometric verification is very quick and is often used in commercial applications. It is private and efficient and often requires two-factor authentication – something you have or know plus your fingerprint that identifies who you are.
Enrolling and verifying individuals using this process doesn’t demand huge processing power and is ideally suited to the growing trend in enterprise mobility.
Users can simply store their own biometric data on their own devices for privacy, portability and convenience. Of the two types of biometric application, this is the simplest and most easily found on smaller devices and has recently grown in popularity within the consumer space.
When you use your finger to access your phone, this is defined as biometric verification. The device uses your singular print stored in its database to confirm that you are who you claim to be, further backed up by passwords and PIN numbers.
Biometric identification is more complex and requires a system that’s advanced and comprehensive. An example of this would be when you access your bank account using a biometric pad at the teller, or when you are applying for specific government papers and the system checks your fingerprint against a vast database of prints and identities.
Biometric verification is the hurdle you jump to prove that you are who you say you are, biometric identification is when a system identifies you from within a vast database.
Both systems are invaluable when it comes to protecting your identity and assets, but the latter demands a level of sophistication in technology to manage a significantly larger database and it is prohibitive for more basic devices and biometric systems.
Whether you are about to use biometrics to identify or verify, your fingerprint remains your own proof of who you are. It is unique to you and you alone, and it is your highly personalised key to unlocking your world.
Quoted sources: http://www.paymentscardsandmobile.com/consumer-demand-banks-adopt-biometric-technology-doubles/
E-Business
Kaspersky Uncovers New Mirage Kitten Malware Used in Cyber-espionage Campaign Across Africa, Others
Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The findings were revealed at its annual Kaspersky Cyber Security Weekend for the Middle East, Turkiye and Africa (META).
![]()
The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.
The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organisations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organisations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.
The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioural similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots.
It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network.
This lets them slip past network defences and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.
While the initial access vector remains unclear in most cases, Kaspersky GReAT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organisation in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods.
The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.
“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa.
“Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts.
“Given the persistence and sophistication of these techniques, organisations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.
E-Business
NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

Nigeria Data Protection Commission (NDPC) has directed all Data Controllers and Data Processors of Major Importance (DCPMIs), yet to register with the commission to do so immediately.

This followed a Federal High Court judgment affirming NDPC statutory powers to designate and register such entities.
DCPMIs are entities operating in Nigeria that handle sensitive personal data or large volumes of information, requiring mandatory registration with the NDPC under the Nigeria Data Protection Act (NDPA).
In a statement issued on Tuesday by Babatunde Bamigboye, head of Legal, Enforcement and Regulations at the NDPC, described the judgment as a major milestone for data accountability and regulatory oversight in Nigeria.
The commission said the ruling arose from a suit filed by Emmanuel Harunna against the NDPC in Emmanuel Harunna v. NDPC (FHC/L/CS/1116/2024), in which the applicant sought a declaration that Point of Sale agents were not Data Controllers or Processors of Major Importance under the Nigeria Data Protection Act and requested a perpetual injunction restraining the commission from registering them.
According to the statement, Justice F.N. Ogazi examined the commission’s Guidance Notice on Registration alongside Sections 5(d), 6(c), 44, 45 and 65 of the Nigeria Data Protection Act before concluding that the commission acted within its statutory powers in designating entities under the Major Data Processing – Ordinary High Level category as Data Controllers and Processors of Major Importance.
Quoting the judgment, the statement read, “The Nigeria Data Protection Act was enacted to promote accountability, transparency and responsible data governance. Registration enables the Respondent to identify entities engaged in significant data processing activities, monitor compliance.”
It added that the court held that, “Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”
The statement further quoted the court as saying, “Looking at the recitals of the Guidance Notice, there is every indication that the Guidance Notice is also aimed at protecting the privacy and security of data subjects, thus bringing the registration requirement of the Guidance Notice within the protective shield of Section 45 of the 1999 Constitution.”
According to the commission, the court also held that, “Remarkably, Section 63 of the Data Protection Act provides that the provisions of the Act shall prevail over any other law inconsistent with its provisions on matters relating to the processing of personal data.”
Reacting to the judgment, the commission described the decision as a significant boost to Nigeria’s data protection regime.
“The Commission appreciates the ground-breaking efforts of the court towards the advancement of the jurisprudence relating to data accountability in Nigeria, as eloquently demonstrated in this case,” the statement read.
Following the ruling, Vincent Olatunji, national commissioner and chief executive officer, had directed every Data Controller and Processor of Major Importance that had yet to comply with the registration requirement to register without delay.
The commission warned that entities failing to comply with the registration requirement could face legal consequences.
“Failure to register creates serious legal liabilities under the law, while compliance with registration requirements builds public trust and safeguards the fundamental rights and freedoms of data subjects in Nigeria,” the statement added.
E-Business
UNN to Partner Firm on AI, Smart Mobility Innovation Centre

The University of Nigeria (UNN) is set to partner with The Roxettes Group to establish a research and innovation centre focused on artificial intelligence (AI), smart and green mobility, and digital technologies, in a move aimed at strengthening research, entrepreneurship and technology-driven industrial development.

Chairman of The Roxettes Group, Arc. Dr. Kaycee Orji-Kelechi, announced the proposed partnership while delivering his acceptance speech after receiving an Honorary Doctor of Business Administration (Honoris Causa) during the university’s convocation ceremony.
The proposed facility, to be known as the Dr. Kaycee Orji Centre for Artificial Intelligence, Smart/Green Mobility and Digital Innovation, is expected to provide a platform for research, innovation and collaboration between academia and industry, with a focus on developing commercially viable solutions to local and continental challenges.
Orji-Kelechi said the initiative was conceived as a long-term investment in human capital and technological advancement rather than simply another physical infrastructure project.
He said the vision was to position the University of Nigeria among Africa’s leading institutions in artificial intelligence, smart mobility and digital innovation through research, entrepreneurship and technology development.
According to him, the centre will house five specialised laboratories covering artificial intelligence and machine learning, smart and green mobility, robotics and the Internet of Things (IoT), digital finance and financial technology, as well as cloud computing and advanced data centre technologies.
He also announced plans for the proposed Kaycee Orji Founders Innovation Challenge, an annual programme intended to identify, mentor and support innovative ideas from students, researchers and academic staff with the potential to become scalable businesses.
“Every student of this University should know that a great idea conceived in a classroom should have a pathway to becoming a patent, a startup, a global enterprise, and a solution that transforms society,” he said.
Orji-Kelechi disclosed that preliminary conceptual work on the project had commenced, with architectural and engineering designs being prepared by K.KH Contractors Ltd., a subsidiary of The Roxettes Group.
He added that discussions with the university would begin on identifying a suitable site for the project, while a comprehensive proposal containing architectural drawings, engineering designs and an implementation framework would be submitted after completion of the design phase.
Reflecting on his career, Orji-Kelechi said Africa must move beyond consuming innovation to creating it through investment in manufacturing, technology and entrepreneurship.
“We have pursued one simple vision: that Nigeria and Africa must move from consumption to production; from importing innovation to creating it; and from waiting for opportunities to building them,” he said.
He urged graduating students to see their education as a foundation for solving societal challenges through innovation, leadership and enterprise, adding that he remained committed to promoting industrial development, youth empowerment and sustainable economic growth.
The proposed collaboration forms part of broader efforts to strengthen university-industry partnerships, which are increasingly seen as critical to improving research commercialisation, innovation capacity and technology-led economic development in Nigeria.
News2 days agoHistory as Lagos Becomes First Nigerian State to Launch Greenhouse Gas Registry
E-Business2 days agoUNN to Partner Firm on AI, Smart Mobility Innovation Centre
Telecom2 days agoAI Investment Gap Threatens Africa’s Future Growth
Telecom2 days agoAMCON Puts ntel Up for Sale, Seeks Investors
Telecom1 day agoFact-Check: Elon Musk’s “Tesla Pi Phone” is Internet Rumor
E-Financial2 days agoRemita Raises Alarm Over Nigeria’s Digital Divide, Calls for More Investment
Telecom2 days agoCourt Affirms NDPC’s Powers to Register Major Data Controllers, Processors
General News2 days agoPan-Africanism: Why Integration is Non-Negotiable for Africa’s Future













